ZeroHour

Incidents

Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups

Ransomware & extortion groups · activity

#Group7dtrend30d90dall-time*Last postStatusEstimated earnings (public reporting)
1the gentlemen30▲8152400400activeno public figure
2qilin29▲16113364364activeno public figure
3storm9▼31496161activeno public figure
4krybit15▲15449595activeno public figure
5akira10▲3438787activeApproximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.
6direwolf2▼9376262activeno public figure
7coinbase cartel0=355656activeno public figure
8inc ransom10▲634113113activeno public figure
9lockbit55=275454activeOver US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…
10audit team10▲1242626activeno public figure
11safepay9▼2226767activeno public figure
12leakeddata1▲1203939activeno public figure
13orova0=194444activeno public figure
14emperador5=192323activeno public figure
15zawoo0=191919activeno public figure
16kazu0▼17171717activeno public figure
17vexy4▼3161616activeno public figure
18shinyhunters2=143232activeno public figure
19panzer7▲6142525activeno public figure
20black nevas1▼12141414activeno public figure
21play3▼1134747activeno public figure
22chaos3▼1133535activeno public figure
23rhysida2▼2131515activeno public figure
24pear0▼1122323activeno public figure
25cyberleek0=121212activeno public figure

*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.

Incidents20 records · full details

VictimGroup / typeDiscoveredDetails
BN: higuchi-inc Report Error & Data Leak Warning⁠
tracker page ↗
stormousfilter this group · Jul 2, 2026www.higuchi-inc.co.jp/newsrelease/company/doc/unauthorized_access_incident.pdf // We have reviewed the report issued by HIGUCHI INC. To correct their mistake: the breach did not affect just one branch, but rather 3 different branches across various regions.Your data has not been leaked yet, as you are currently within an 8-day grace period. Before we publish any of your commercial or personal data, be aware that we possess 102 GB of Sage software backups, alongside numerous commercial documents.We await your reply to our messages. Follow the correct path to ensure nothing is leaked. We are waiting for you.
Notice
tracker page ↗
stormousfilter this group · Jul 2, 2026We will soon terminate our operations and services. All hosted data is scheduled for complete erasure within 60 days, before this blog goes offline permanently.
maglificioliliana.com UPDATE-FULL DATA DUMP FREE PART1
tracker page ↗
stormousfilter this group · Jun 28, 2026Over +10GB GB of data has been accessed and exfiltrated. This includes product designs, historical fashion lines, and technical specifications for garments. Furthermore, we have obtained customer databases from various parts of the world, financial records, commercial contracts, employee data, personal files for all staff members within the network, daily operational documents, and more.
lorenzoni-store.com UPDATE-FULL DATA DUMP FREE PART1
tracker page ↗
stormousfilter this group · Jun 28, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
montechiaro-store.com UPDATE-FULL DATA DUMP FREE PART1
tracker page ↗
stormousfilter this group · Jun 28, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
impulso-store.com UPDATE-FULL DATA DUMP FREE PART1
tracker page ↗
stormousfilter this group · Jun 28, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
higuchi-inc.co.jp
tracker page ↗
stormousfilter this group · Jun 28, 2026(Dallas - HongKong - LosAngeles ) Comprehensive financial statements including Balance Sheets, Asset records, Liabilities, Capital, Accounts Receivable (A/R), and Accounts Payable (A/P) database backups from Sage 50 (formerly Peachtree Accounting software), indicated by the ⁠.ptb⁠ file extension Corporate data detailing domestic and international inventory tracking, trade checking, and business operations.
HIGUCHI USA, INC
tracker page ↗
stormousfilter this group · Jun 28, 2026(Dallas - HongKong - LosAngeles ) Comprehensive financial statements including Balance Sheets, Asset records, Liabilities, Capital, Accounts Receivable (A/R), and Accounts Payable (A/P) database backups from Sage 50 (formerly Peachtree Accounting software), indicated by the ⁠.ptb⁠ file extension Corporate data detailing domestic and international inventory tracking, trade checking, and business operations.
eogb.co.uk
tracker page ↗
stormousfilter this group · Jun 28, 2026Deep access to Microsoft Dynamics GP containing complete corporate accounting, invoices, vendor details, and commercial transactions.Access to internal legal documents, partnership agreements, and customer contracts (such as CBIF OSMO agreements).Exfiltration of operational spreadsheets, financial reports, and executive documents via corporate
eshacloudqa.com
tracker page ↗
stormousfilter this group · Jun 28, 2026We have breached ESHA Research / ESHA Cloud Services and compromised their core product development databases. The exfiltrated data includes highly confidential industry secrets and formulation data Complete intellectual property containing secret product designs, manufacturing blueprints, and recipes (⁠SupplementFormula⁠, ⁠PureFood⁠, ⁠FoodGroup⁠).Deep laboratory data, nutritional testing breakdowns, and allergen classification records (⁠SupplementIngredient⁠, ⁠Analysis⁠, ⁠AllergenGroup⁠, Sensitive registries containing client profiles, user metrics, and market consumer data (⁠Consumer⁠, ⁠Activity⁠).
monoprix.tn
tracker page ↗
stormousfilter this group · Jun 28, 2026Data description: Pending update
Official Statement: Protecting palatineschool.org Infrastructure
tracker page ↗
stormousfilter this group · Jun 28, 2026During our routine network security audits, our team discovered critical structural vulnerabilities within Palatine School, which granted us full, unrestricted access to their central server (PALDC2020). We had the technical capacity to access every directory, including pupil databases (⁠ StudentData NHS NO ) ⁠, ⁠Pupil Admin - Users -FocusIT⁠) and staff records ⁠Personnel⁠.We want to announce that we have locked down this operation and decided to leak absolutely nothing.This is an institution dedicated to children and special needs education. Unlike corporate thieves or ruthless threat actors, we operate with a strict code of ethics: we do not target children, schools, or healthcare facilities.Instead of destroying them, we have chosen to act as an uninvited security audit. We are using our platform to publicly invite the administration of Palatine School to contact us privately. We will provide them with the full technical details of the critical vulnerabilities we discovered and guide them on how to patch their system for free, ensuring they are protected from other ruthless cyber criminals.
Data Leak Update
tracker page ↗
stormousfilter this group · Jun 26, 2026** Do ML IT and vspsolutions.com.au think they are smarter than us? They are reporting the links where the data was uploaded, and they are being disabled. Therefore, and officially, we are preparing a private server on the Tor network to dump all the data of these companies and the data of others. Which will be available to everyone 24/7 along with a clear view of the extracted data, employees
mlit.com.my UPDATE-FULL DATA DUMP NEW LINK 10GB
tracker page ↗
stormousfilter this group · Jun 24, 2026FULL DATA DUMP . The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases.
jaggroup.com UPDATE-FULL DATA DUMP NEW LINK
tracker page ↗
stormousfilter this group · Jun 24, 2026Full database containing corporate emails (⁠@jaggroup.com⁠), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (⁠zBackups.zip⁠, ⁠wetransfer⁠ packages), SQL server connection data, and ⁠IM.mdb⁠ database files.Internal project management sheets (⁠Jag Project.xlsx⁠), user listings, purchasing, and sales import logs.
maglificioliliana.com
tracker page ↗
stormousfilter this group · Jun 24, 2026Over 400 GB of data has been accessed and exfiltrated. This includes product designs, historical fashion lines, and technical specifications for garments. Furthermore, we have obtained customer databases from various parts of the world, financial records, commercial contracts, employee data, personal files for all staff members within the network, daily operational documents, and more.
lorenzoni-store.com
tracker page ↗
stormousfilter this group · Jun 24, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
montechiaro-store.com
tracker page ↗
stormousfilter this group · Jun 24, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
impulso-store.com
tracker page ↗
stormousfilter this group · Jun 24, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
jaggroup.com UPDATE-FULL DATA DUMP
tracker page ↗
stormousfilter this group · Jun 22, 2026Full database containing corporate emails (⁠@jaggroup.com⁠), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (⁠zBackups.zip⁠, ⁠wetransfer⁠ packages), SQL server connection data, and ⁠IM.mdb⁠ database files.Internal project management sheets (⁠Jag Project.xlsx⁠), user listings, purchasing, and sales import logs.

Breach & ransomware newsAll →

Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.